← Trust center

Security

No rights on your cluster. Per-project permissions. Agents under control.

graal is designed for your CISO’s review: a privilege-free installation, federated identities, a record of every action, and no data sent outside.

Isolation

What graal asks of your cluster

An access review does not have to take our documentation on trust: the rendered chart can be reviewed, object by object.

No rights on the cluster

No custom resources, no cluster-wide role: graal works with only the rights your platform team grants it.

See the technical specification

Restricted pods, no exceptions

Every pod, including your workloads, runs under PSA restricted: non-privileged user, Linux capabilities dropped, default seccomp profile.

A closed network per workload

Each run gets its own network policy: it cannot reach another project or another organization, and its egress is limited to authorized destinations.

Images under control

Workloads only pull images from authorized registries, pinned by digest: no arbitrary image starts.

Identity

Who can do what, on what

Roles and their holders are visible in the console, and revoked in the same place.

The roles screen of the graal console: five system roles (job reader, contributor, project owner and reader, organization administrator), with their description and number of holders.

The roles of an organization: what each one can do, and on what.

Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).

Your SSO, your directory

OIDC or SAML federation, LDAP or Active Directory, enforceable multi-factor authentication.

The project is the unit of permissions

Roles per resource, groups from your directory, assignments revoked in one click.

One organization, one directory

Each organization has its own authentication realm: isolation is an identity boundary, not a column in a table.

AI agents

Agents that act, under your rules

An AI agent holds permissions like anyone else: it authenticates, is scoped to one project, is traced, and can be revoked.

The Agents panel of the graal console, open next to the job list: three connected agents with their read or write permissions, then the live activity feed of their MCP tool calls (reading logs, running, scheduling and creating a job).The Agents panel of the graal console, open next to the job list: three connected agents with their read or write permissions, then the live activity feed of their MCP tool calls (reading logs, running, scheduling and creating a job).

The Agents panel: connected agents, their permissions, and every tool call they make, live.

Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).

One service account per project

The agent acts under its own identity, never under that of the person who created it.

Human approval

Sensitive actions wait for approval from an authorized person other than the agent’s creator.

Per-agent policies

Allowed operations, projects, maximum cost and time windows, agent by agent.

No destructive tool enabled by default

An agent creates, runs and schedules; deleting remains an explicit choice on your side.

Visible and revocable

Every call shows up live in the console; removing a permission takes effect on the next request.

The model of your choice

Hosted on your premises or with the provider you select: an external model only receives what the tools return to it.

Explore AI agents

Secrets

Encrypted in the database, delivered in memory

A workload needs to reach a database; the password that allows it must neither be readable in clear text nor travel.

Encrypted in the database

Sealed with AES-256-GCM, with one key per organization derived from a root key by HKDF-SHA256. The secret’s name is used as authenticated data: moved elsewhere, it no longer decrypts.

Delivered in memory

A workload receives its secrets at startup, in memory: they appear neither in pod specs nor in logs.

Referenced, never copied

Connectors and pipelines reference a secret by name: exported code contains no password.

Audit

Every action leaves a record

The same trail for people and for agents, reviewable and exportable.

  • Who did what, on which resource, with what result, person or agent
  • The source address of every request
  • Logins, access denials and revocations
  • Approvals granted or refused to agents
  • A trail you can export to your SIEM
  • Costs and quotas, project by project

Nothing leaves

What graal does not send, and what it ships

The platform needs no outside service to work.

No telemetry

graal sends nothing to the vendor: no usage statistics, no error reports, no data from your projects.

No third-party service

No SaaS, no external fonts, no external captcha: the platform works on a closed network.

A verifiable supply chain

Signed images pinned by digest, and a software bill of materials (SBOM) shipped with every release.

Reporting

Report a vulnerability

Write to security@graal.systems. We acknowledge, fix, and keep you informed until publication.

Put graal in front of your security teams

Rendered chart, list of requested rights, permission model and answers to your questionnaires: on request.